| *** sapd1 has joined #openstack-keystone | 01:05 | |
| *** imacdonn has quit IRC | 01:13 | |
| *** imacdonn has joined #openstack-keystone | 01:14 | |
| *** altlogbot_2 has quit IRC | 01:28 | |
| *** altlogbot_1 has joined #openstack-keystone | 01:31 | |
| *** hemna_ has quit IRC | 01:34 | |
| *** adriant has joined #openstack-keystone | 01:36 | |
| *** hemna_ has joined #openstack-keystone | 01:38 | |
| *** jamesmcarthur has quit IRC | 02:00 | |
| *** lbragstad has quit IRC | 02:57 | |
| *** whoami-rajat has joined #openstack-keystone | 03:12 | |
| *** jamesmcarthur has joined #openstack-keystone | 03:20 | |
| *** jamesmcarthur has quit IRC | 03:33 | |
| *** shyamb has joined #openstack-keystone | 03:40 | |
| *** jamesmcarthur has joined #openstack-keystone | 04:01 | |
| *** jamesmcarthur has quit IRC | 04:05 | |
| *** etp has joined #openstack-keystone | 04:13 | |
| *** jamesmcarthur has joined #openstack-keystone | 04:19 | |
| *** shyamb has quit IRC | 04:20 | |
| *** jamesmcarthur has quit IRC | 04:29 | |
| *** rcernin has quit IRC | 04:30 | |
| *** rcernin has joined #openstack-keystone | 04:31 | |
| *** jamesmcarthur has joined #openstack-keystone | 04:32 | |
| *** pcaruana has joined #openstack-keystone | 04:35 | |
| *** pcaruana has quit IRC | 04:38 | |
| *** vishakha has joined #openstack-keystone | 04:45 | |
| openstackgerrit | guang-yee proposed openstack/keystone master: update documentation for X.509 tokenless auth https://review.opendev.org/669790 | 04:59 |
|---|---|---|
| *** gyee has quit IRC | 04:59 | |
| *** ileixe has quit IRC | 04:59 | |
| *** ileixe has joined #openstack-keystone | 05:01 | |
| *** ileixe has quit IRC | 05:03 | |
| *** ileixe has joined #openstack-keystone | 05:03 | |
| *** jamesmcarthur has quit IRC | 05:05 | |
| openstackgerrit | Merged openstack/keystone master: nit: remove some useless code https://review.opendev.org/612625 | 05:18 |
| *** ivve has joined #openstack-keystone | 05:19 | |
| ivve | Either [None] key_repository does not exist or Keystone does not have sufficient permission to access it: /etc/keystone/credential-keys/ | 05:36 |
| *** shyamb has joined #openstack-keystone | 05:36 | |
| ivve | was checking this | 05:37 |
| ivve | https://github.com/openstack/keystone/blob/106b28ad4c30948c293dc9200adb908893b24a35/keystone/common/fernet_utils.py#L37-L73 | 05:37 |
| ivve | using fernet with keystone.conf defaults | 05:38 |
| ivve | this just appeared out of nowhere and became worse and worse | 05:39 |
| ivve | keystone is working fine though | 05:39 |
| ivve | there is no such directory at all | 05:39 |
| ivve | i tried creating it and giving proper permissions so thats not it | 05:39 |
| ivve | restarting and rotating keys does nothing | 05:40 |
| *** shyam89 has joined #openstack-keystone | 05:41 | |
| ivve | tried looking for bugs but can't find anyhing related | 05:41 |
| *** shyamb has quit IRC | 05:41 | |
| *** jamesmcarthur has joined #openstack-keystone | 05:44 | |
| *** jamesmcarthur has quit IRC | 05:51 | |
| *** rcernin has quit IRC | 05:57 | |
| *** vishalmanchanda has joined #openstack-keystone | 06:05 | |
| *** jamesmcarthur has joined #openstack-keystone | 06:24 | |
| *** jamesmcarthur has quit IRC | 06:28 | |
| *** etp has quit IRC | 06:38 | |
| *** dancn has joined #openstack-keystone | 06:40 | |
| *** shyam89 has quit IRC | 06:52 | |
| *** jamesmcarthur has joined #openstack-keystone | 06:59 | |
| *** shyamb has joined #openstack-keystone | 07:02 | |
| *** pcaruana has joined #openstack-keystone | 07:03 | |
| *** jamesmcarthur has quit IRC | 07:05 | |
| *** awalende has joined #openstack-keystone | 07:16 | |
| *** ianw is now known as ianw_pto | 07:16 | |
| *** shyamb has quit IRC | 07:40 | |
| *** shyamb has joined #openstack-keystone | 07:44 | |
| *** starborn has joined #openstack-keystone | 07:49 | |
| *** shyamb has quit IRC | 07:50 | |
| *** rcernin has joined #openstack-keystone | 08:02 | |
| *** awalende has quit IRC | 08:04 | |
| *** awalende has joined #openstack-keystone | 08:05 | |
| *** rcernin has quit IRC | 08:11 | |
| *** shyamb has joined #openstack-keystone | 08:23 | |
| *** dancn has quit IRC | 08:24 | |
| *** rcernin has joined #openstack-keystone | 08:27 | |
| *** dancn has joined #openstack-keystone | 08:29 | |
| *** tkajinam has quit IRC | 08:42 | |
| openstackgerrit | Vishakha Agarwal proposed openstack/keystone master: Fix keystone document https://review.opendev.org/669818 | 08:54 |
| *** jamesmcarthur has joined #openstack-keystone | 09:01 | |
| *** jamesmcarthur has quit IRC | 09:05 | |
| *** jamesmcarthur has joined #openstack-keystone | 09:32 | |
| *** jamesmcarthur has quit IRC | 09:37 | |
| *** shyamb has quit IRC | 09:40 | |
| *** pcaruana has quit IRC | 09:48 | |
| *** shyamb has joined #openstack-keystone | 09:52 | |
| *** dancn has quit IRC | 09:57 | |
| openstackgerrit | Vishakha Agarwal proposed openstack/keystone master: Remove [signing] config https://review.opendev.org/659434 | 10:22 |
| *** xek_ is now known as xek | 10:32 | |
| *** shyamb has quit IRC | 10:35 | |
| *** shyamb has joined #openstack-keystone | 10:52 | |
| *** dancn has joined #openstack-keystone | 11:11 | |
| *** tesseract has joined #openstack-keystone | 11:11 | |
| *** tesseract has quit IRC | 11:13 | |
| *** tesseract has joined #openstack-keystone | 11:15 | |
| *** altlogbot_1 has quit IRC | 11:19 | |
| *** irclogbot_3 has quit IRC | 11:19 | |
| *** altlogbot_3 has joined #openstack-keystone | 11:20 | |
| *** tesseract has quit IRC | 11:23 | |
| *** altlogbot_3 has quit IRC | 11:25 | |
| *** jamesmcarthur has joined #openstack-keystone | 11:34 | |
| *** jamesmcarthur has quit IRC | 11:39 | |
| *** jistr_ has joined #openstack-keystone | 11:51 | |
| *** niceplace_ has joined #openstack-keystone | 11:52 | |
| *** kinrui has joined #openstack-keystone | 11:53 | |
| *** jistr has quit IRC | 11:55 | |
| *** aprice has quit IRC | 11:55 | |
| *** niceplace has quit IRC | 11:55 | |
| *** hogepodge has quit IRC | 11:55 | |
| *** mordred has quit IRC | 11:55 | |
| *** BlackDex has quit IRC | 11:55 | |
| *** jamespage has quit IRC | 11:55 | |
| *** kmalloc has quit IRC | 11:55 | |
| *** TheJulia has quit IRC | 11:55 | |
| *** dustinc has quit IRC | 11:55 | |
| *** jrosser has quit IRC | 11:55 | |
| *** fungi has quit IRC | 11:55 | |
| *** melwitt has quit IRC | 11:56 | |
| *** Krenair has quit IRC | 11:58 | |
| *** shyamb has quit IRC | 11:59 | |
| *** rcernin has quit IRC | 11:59 | |
| *** irclogbot_0 has joined #openstack-keystone | 12:00 | |
| *** aprice has joined #openstack-keystone | 12:01 | |
| *** hogepodge has joined #openstack-keystone | 12:01 | |
| *** jamespage has joined #openstack-keystone | 12:01 | |
| *** mordred has joined #openstack-keystone | 12:01 | |
| *** BlackDex has joined #openstack-keystone | 12:01 | |
| *** kmalloc has joined #openstack-keystone | 12:01 | |
| *** TheJulia has joined #openstack-keystone | 12:01 | |
| *** dustinc has joined #openstack-keystone | 12:01 | |
| *** jrosser has joined #openstack-keystone | 12:01 | |
| *** altlogbot_2 has joined #openstack-keystone | 12:02 | |
| *** raildo has joined #openstack-keystone | 12:03 | |
| *** altlogbot_2 has quit IRC | 12:05 | |
| *** irclogbot_0 has quit IRC | 12:05 | |
| *** jamesmcarthur has joined #openstack-keystone | 12:07 | |
| *** altlogbot_1 has joined #openstack-keystone | 12:08 | |
| *** pcaruana has joined #openstack-keystone | 12:10 | |
| *** altlogbot_1 has quit IRC | 12:11 | |
| *** jamesmcarthur has quit IRC | 12:11 | |
| *** kinrui is now known as fungi | 12:21 | |
| *** shyamb has joined #openstack-keystone | 12:26 | |
| *** jistr_ is now known as jistr | 12:33 | |
| *** jamesmcarthur has joined #openstack-keystone | 12:45 | |
| *** altlogbot_3 has joined #openstack-keystone | 12:54 | |
| *** altlogbot_3 has quit IRC | 12:57 | |
| *** lbragstad has joined #openstack-keystone | 13:15 | |
| *** shyamb has quit IRC | 13:23 | |
| *** vishakha has quit IRC | 13:33 | |
| *** jamesmcarthur has quit IRC | 13:49 | |
| *** cwright has quit IRC | 13:59 | |
| *** cwright has joined #openstack-keystone | 14:00 | |
| *** ayoung has joined #openstack-keystone | 14:02 | |
| *** jamesmcarthur has joined #openstack-keystone | 14:17 | |
| *** whoami-rajat has quit IRC | 14:18 | |
| cmurphy | would anybody care to moderate today's meeting for me? I have a conflicting meeting that I'd like to give partial attention to | 14:22 |
| *** BlackDex has quit IRC | 14:25 | |
| *** BlackDex has joined #openstack-keystone | 14:27 | |
| *** jamesmcarthur has quit IRC | 14:34 | |
| *** awalende has quit IRC | 14:34 | |
| *** jamesmcarthur has joined #openstack-keystone | 14:35 | |
| *** awalende has joined #openstack-keystone | 14:35 | |
| lbragstad | cmurphy sure - i can do that | 14:36 |
| cmurphy | thanks lbragstad | 14:37 |
| *** awalende has quit IRC | 14:39 | |
| lbragstad | np | 14:40 |
| *** BlackDex has quit IRC | 14:47 | |
| *** BlackDex has joined #openstack-keystone | 14:48 | |
| *** starborn has quit IRC | 14:48 | |
| *** ivve has quit IRC | 14:53 | |
| openstackgerrit | Gauvain Pocentek proposed openstack/keystone master: Make application credentials work with group-assigned roles https://review.opendev.org/669886 | 15:03 |
| *** dancn has quit IRC | 15:08 | |
| kmalloc | i might miss the meeting today | 15:11 |
| kmalloc | dealing with a sick dog. | 15:11 |
| kmalloc | just jumped/lunged at our walker because he's not feeling well. | 15:11 |
| *** altlogbot_2 has joined #openstack-keystone | 15:12 | |
| *** altlogbot_2 has quit IRC | 15:17 | |
| *** altlogbot_2 has joined #openstack-keystone | 15:42 | |
| *** altlogbot_2 has quit IRC | 15:47 | |
| *** vishakha has joined #openstack-keystone | 15:56 | |
| *** altlogbot_0 has joined #openstack-keystone | 16:08 | |
| *** ivve has joined #openstack-keystone | 16:08 | |
| *** njohnston has joined #openstack-keystone | 16:09 | |
| *** altlogbot_0 has quit IRC | 16:13 | |
| *** altlogbot_3 has joined #openstack-keystone | 16:20 | |
| *** whoami-rajat has joined #openstack-keystone | 16:20 | |
| *** altlogbot_3 has quit IRC | 16:23 | |
| *** irclogbot_3 has joined #openstack-keystone | 16:24 | |
| *** irclogbot_3 has quit IRC | 16:27 | |
| openstackgerrit | Merged openstack/keystone-specs master: Add spec for immutable resources https://review.opendev.org/624692 | 16:32 |
| *** altlogbot_2 has joined #openstack-keystone | 17:00 | |
| *** altlogbot_2 has quit IRC | 17:05 | |
| *** irclogbot_2 has joined #openstack-keystone | 17:10 | |
| *** irclogbot_2 has quit IRC | 17:13 | |
| njohnston | lbragstad: Hi, I was wondering if I could ask for your help; mlavalle suggested you'd be a good person to contact. I am working on https://bugs.launchpad.net/neutron/+bug/1720486 | 17:38 |
| openstack | Launchpad bug 1720486 in neutron "ValueError: Circular reference detected when enable keystonemiddle audit" [Medium,Confirmed] - Assigned to Liyingjun (liyingjun) | 17:38 |
| *** gyee has joined #openstack-keystone | 17:39 | |
| njohnston | lbragstad: There's a proposed solution in keystonemiddleware but it's downvoted with indications that the fix should be in neutron - but as I look at the neutron codebase I don't see where keystonemiddleware (or filter_factory) gets called in the neutron code that could be altered to prevent this. | 17:40 |
| *** tesseract has joined #openstack-keystone | 17:40 | |
| kmalloc | hey | 17:43 |
| kmalloc | sorry for missing the meeting | 17:43 |
| kmalloc | sick dog =/ dealing with that among other things | 17:43 |
| kmalloc | lbragstad, cmurphy: changing a 500 -> 4XX is a better choice IMO, but a 500 is fine really | 17:44 |
| kmalloc | i would like to go with easiest to maintain | 17:44 |
| cmurphy | hmm | 17:47 |
| lbragstad | njohnston o/ | 17:52 |
| njohnston | lbragstad o/ | 17:53 |
| *** dancn has joined #openstack-keystone | 17:53 | |
| lbragstad | njohnston is there a ksm patch floating around somewhere? | 17:53 |
| njohnston | lbragstad: https://review.opendev.org/#/c/508659/ | 17:54 |
| openstackgerrit | Merged openstack/keystone master: Fix keystone document https://review.opendev.org/669818 | 17:54 |
| lbragstad | trying to refresh myself | 17:55 |
| lbragstad | looks like it's been a while | 17:55 |
| lbragstad | was one of the alternatives to not use `neutron_context` and instead just name the context `context`? | 17:56 |
| njohnston | lbragstad: wouldn't that have the same issue? In the bug, the nova guys talk about how they had to pop the context out of the notification entirely. | 17:57 |
| lbragstad | digging up the nova patch | 17:58 |
| njohnston | lbragstad: https://review.opendev.org/446948 | 17:58 |
| lbragstad | aha - sure | 17:58 |
| lbragstad | https://review.opendev.org/#/c/446948/1/nova/exception_wrapper.py,unified | 17:58 |
| lbragstad | i think it would be reasonable to do this ksm if we're dealing with a generic name for context (as opposed to neutron_context) | 18:00 |
| njohnston | right. but the traces in the bug don't give an indication which notification it might be that neutron is passing through keystonemiddleware to cause this issue | 18:00 |
| njohnston | lbragstad: so if I was able to change neutron to use 'service_context' instead of 'neutron_context' then the ksm patch could key off of that perhaps? | 18:01 |
| lbragstad | i think something to that effect might get us closer, yes | 18:01 |
| lbragstad | mainly because it makes things more generic and it's reuseable across services | 18:02 |
| lbragstad | otherwise, ksm needs a patch for each project that is using some sort of $project_context naming convention | 18:02 |
| njohnston | right. ok, so I'll propose a change in neutron and update the ksm change | 18:03 |
| njohnston | lbragstad: Thanks very much! | 18:03 |
| lbragstad | iiuc - it looks like that was the main concern behind the current proposal in 508659 | 18:03 |
| lbragstad | njohnston no problem | 18:03 |
| kmalloc | cmurphy: i should have the SQL migrations up tonight. | 18:15 |
| kmalloc | cmurphy: they're doing construction nearby and i can't get anything done (like right outside my front door) atm | 18:15 |
| ayoung | kmalloc, you do all of your work in Docker, right? | 18:17 |
| cmurphy | kmalloc: blegh :( | 18:17 |
| *** jamesmcarthur has quit IRC | 18:21 | |
| *** dancn has quit IRC | 18:23 | |
| *** whoami-rajat has quit IRC | 18:30 | |
| *** jamesmcarthur has joined #openstack-keystone | 18:34 | |
| *** melwitt has joined #openstack-keystone | 18:35 | |
| *** irclogbot_0 has joined #openstack-keystone | 18:36 | |
| *** tesseract has quit IRC | 18:39 | |
| *** irclogbot_0 has quit IRC | 18:39 | |
| openstackgerrit | Merged openstack/python-keystoneclient master: Blacklist bandit 1.6.0 & cap sphinx for 2.7 https://review.opendev.org/660609 | 18:40 |
| openstackgerrit | Lance Bragstad proposed openstack/keystone-specs master: Expose root domain as assignment target https://review.opendev.org/661837 | 18:59 |
| *** lbragstad has quit IRC | 20:02 | |
| *** vishakha has quit IRC | 20:04 | |
| *** ivve has quit IRC | 20:06 | |
| *** xek has quit IRC | 20:21 | |
| *** irclogbot_3 has joined #openstack-keystone | 20:24 | |
| *** irclogbot_3 has quit IRC | 20:27 | |
| *** jamesmcarthur has quit IRC | 20:40 | |
| *** jamesmcarthur has joined #openstack-keystone | 20:41 | |
| *** jamesmcarthur has quit IRC | 20:48 | |
| *** lbragstad has joined #openstack-keystone | 20:56 | |
| *** jmlowe has joined #openstack-keystone | 21:10 | |
| *** irclogbot_1 has joined #openstack-keystone | 21:14 | |
| *** pcaruana has quit IRC | 21:19 | |
| *** irclogbot_1 has quit IRC | 21:19 | |
| *** raildo has quit IRC | 21:27 | |
| *** irclogbot_2 has joined #openstack-keystone | 21:38 | |
| *** irclogbot_2 has quit IRC | 21:43 | |
| *** jmlowe has quit IRC | 21:51 | |
| *** jmlowe has joined #openstack-keystone | 21:53 | |
| *** irclogbot_2 has joined #openstack-keystone | 21:54 | |
| *** altlogbot_3 has joined #openstack-keystone | 21:55 | |
| *** altlogbot_3 has quit IRC | 21:55 | |
| *** irclogbot_2 has quit IRC | 21:59 | |
| *** rcernin has joined #openstack-keystone | 22:10 | |
| *** jamesmcarthur has joined #openstack-keystone | 22:21 | |
| *** awalende has joined #openstack-keystone | 22:37 | |
| *** awalende has quit IRC | 22:42 | |
| *** altlogbot_0 has joined #openstack-keystone | 22:44 | |
| *** Krenair has joined #openstack-keystone | 22:47 | |
| *** altlogbot_0 has quit IRC | 22:49 | |
| *** tkajinam has joined #openstack-keystone | 22:52 | |
| kmalloc | ayoung: yes i did for a while | 23:12 |
| *** jamesmcarthur has quit IRC | 23:21 | |
| *** jamesmcarthur has joined #openstack-keystone | 23:42 | |
| gyee | cmurphy, lbragstad, https://bugs.launchpad.net/keystone/+bug/1813335 is not related to x.509. I think the doc is wrong. X.509 should always be used with federation. | 23:42 |
| openstack | Launchpad bug 1813335 in OpenStack Identity (keystone) "x509 configured domains are redundant with auto-generated identity provider domains" [Low,Triaged] | 23:42 |
| gyee | I even go as far as saying the remote user plugin is quite dangerous :-) | 23:42 |
| cmurphy | gyee: you mean instead of 'external' ? | 23:44 |
| cmurphy | i thought x.509 was the classic use case for the external auth method | 23:44 |
| cmurphy | gyee: i'm reviewing your doc change now btw | 23:45 |
| *** jamesmcarthur has quit IRC | 23:46 | |
| gyee | no, x.509 is not designed for external auth | 23:47 |
| gyee | x.509 should always be using the federation mechanism | 23:47 |
| cmurphy | kmalloc: ayoung ^ | 23:48 |
| gyee | external auth, which trust a single attribute (REMOTE_USER), is quite dangerous | 23:48 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!